All reports
Annual report

Quebec Threat Landscape

An annual report on the threat facing Quebec organizations, built on the only Quebec series that exists: the registers of confidentiality incident notices filed with the Commission d’accès à l’information (CAI), obtained through access-to-information requests.

Every fall, once the Commission has tabled its annual report, the same request is filed again and the series grows by one fiscal year. Editions do not replace one another: each keeps its own address, so the series can be read from one year to the next.

Read the 2026 edition

Key figures from the 2026 edition

  • 583incident notices received in 2025-2026
  • 62.8%of 2025-2026 notices involve a malicious cause (366 of 583)
  • 21.3%phishing or social engineering in 2025-2026, 11.5% in 2024-2025
  • 17.7%ransomware in 2025-2026, 21.6% in 2024-2025
  • 8 → 37notices citing both a cyberattack and unauthorized access, 2024-2025 to 2025-2026

Source: CAI register, file AI-2627-216, 1,760 notices over four fiscal years (2022-2023 to 2025-2026).

Editions

  1. 2027Coming fall 2027
  2. 2026Quebec Threat Landscape 2026Four fiscal years of notices reported to Quebec's Commission d'accès à l'information, analyzed sector by sector: in 2025-2026, phishing becomes the second most reported cause and ransomware declines. · 35 min read

How it is built

Every count is recalculated from the register the Commission sends, then checked against the figures it publishes. The methodology and its limits are set out in each edition, section 02.

How to cite this report

CyberAzimut, Quebec Threat Landscape 2026, annual report, September 2026. https://www.cyberazimut.com/en/reports/quebec-threat-landscape/2026

The figures may be reused freely, with credit to the source. Cite the edition (the address with the year) for a figure, and the series (this page) for the approach.